Manual Chapter : Install and License BIG-IQ Centralized Management

Applies To:

Show Versions Show Versions

BIG-IQ Centralized Management

  • 8.2.0, 8.1.0
Manual Chapter

Install and License BIG-IQ Centralized Management

Prepare to license BIG-IQ and perform initial set up tasks

To manage your BIG-IP devices using BIG-IQ, you deploy a BIG-IQ system and then configure it to meet your business needs.
To deploy a BIG-IQ system, you:
  1. Prepare your network environment and architecture (refer to
    Before you deploy a BIG-IQ solution
    in
    Planning a BIG-IQ Centralized Management & Visibility Deployment
    on
    support.f5.com
    for details).
  2. Install and configure the platform you plan to install your software on. The platform can either be a physical device or a virtual device. To use a physical device, you need a BIG-IQ 7000 series device. To use a virtual device, the solution you choose depends on the environment you use. Supported platforms for this release are listed below. Use the guide appropriate for your platform to complete the installation. These guides are posted on
    support.f5.com
    .
    If you choose this platform:
    Refer to this guide for installation details:
    BIG-IQ 7000 Series
    Platform Guide: BIG-IQ 7000 Series
    Amazon Web Services
    F5 BIG-IQ Centralized Management and Amazon Web Services: Setup
    Citrix XenServer:
    F5 BIG-IQ Centralized Management and Citrix XenServer: Setup
    KVM
    F5 BIG-IQ Centralized Management and Linux KVM: Setup
    Microsoft Azure
    F5 BIG-IQ Centralized Management and Microsoft Azure: Setup
    Microsoft Hyper-V
    F5 BIG-IQ Centralized Management and Microsoft Hyper-V: Setup
    VMware NSX-V
    F5 BIG-IQ Centralized Management and VMware ESXi: Setup
    Xen Project
    F5 BIG-IQ Centralized Management and Linux Xen Project: Setup
  3. Deploy, license, and configure the number of BIG-IQ systems you need depending on your high availability and data center requirements.

How do I license BIG-IQ to manage BIG-IP devices?

After you download the software image from the F5 Downloads site and start BIG-IQ in your virtual environment, you can license the system using the base registration key provided by F5. The
base registration key
is a character string the F5 license server uses to provide BIG-IQ a license to access the subscription licensing feature.
You license BIG-IQ in one of the following ways:
  • If the system has access to the Internet, you can have the BIG-IQ system contact the F5 license server and automatically activate the base registration key to get a license.
  • If the system is not connected to the Internet, you can manually license the BIG-IQ using the F5 license server web portal.
  • If the system is in a closed-circuit network (CCN) that does not allow you to export any encrypted information, you must open a case with F5 support at: support.f5.com/csp/my-support/home.

Automatic license and initial setup for BIG-IQ systems

You must have a base registration key before you can license the BIG-IQ system. If you do not have a base registration key, contact the F5 Networks sales group (
f5.com
). After you set up your BIG-IQ VE or set up your BIG-IQ 7000 Series, you can install the BIG-IQ software license.
If the BIG-IQ system is connected to the public internet, you can follow these steps to automatically perform the license activation and perform the initial setup.
  1. Use a browser to log in to BIG-IQ by typing
    https://
    <management_IP_address>
    , where
    <management_IP_address>
    is the address you specified for device management.
    The first time you log in to the BIG-IQ, you use
    admin
    for the
    Username
    and
    Password
    ; but then you must change the admin password.
  2. Change the default admin password.
    1. For
      Current Password
      , type
      admin
      .
    2. Type a new password in the
      New Password
      and
      Re-type New Password
      fields.
    3. Click
      Save
      . BIG-IQ changes the admin password and then displays the initial log in page.
    4. Login to the BIG-IQ user interface using your new password.
    When you change the admin password as part of an initial login, BIG-IQ also resets the root password to match it. During initial setup, you can change them both again.
  3. Select
    License
    .
  4. In
    Base Registration Key
    box, paste the BIG-IQ registration key.
  5. In
    Add-On Keys
    , paste any additional license key you have.
  6. To add another additional add-on key, click the
    +
    sign and paste the additional key in the new
    Add-On Keys
    field.
  7. For
    Activation Method
    , select
    Automatic
    , click the
    Activate
    button, and then click the
    Next
    button.
    If you are setting up BIG-IQ for the first time, the Accept User Legal Agreement screen opens. To accept the license agreement, click the
    Agree
    button, and then click the
    Next
    button.
    BIG-IQ displays the Master Key page.
  8. Type a
    Passphrase
    that satisfies the requirements specified on screen, and then type the same phrase for
    Confirm Passphrase
    , and then click the
    Next
    button.
    BIG-IQ uses the passphrase to generate a master key. For a BIG-IQ high availability (HA) configuration, this passphrase must be the same on all BIG-IQ systems or they won't be able to communicate with each other.
    • Make sure you keep track of the passphrase, because it cannot be recovered if you lose it.
    • You must have the passphrase used to generate the master key before you can change the master key.
    • Finally, when you backup and restore a BIG-IQ, the master key is backed up with the rest of the data, and you cannot restore that data onto a BIG-IQ that has a different master key.
    If you are setting up a Microsoft Azure VE, and you type an entry in any of the fields, you will not be able to continue successfully. The only way to proceed is to leave all of the fields empty and click the
    Next
    button at the bottom of the screen. This allows the system to use the first-time access credentials you specified previously.
  9. Specify an (optional) admin and root password and click the
    Next
    button.
  10. For System Personality, select
    BIG-IQ Central Management
    and click the
    Next
    button.
    You cannot undo this choice. Once you license a device as a BIG-IQ Central Management, you can't change your mind and license it as a BIG-IQ Data Collection Device.
  11. In the
    Hostname
    box, type a fully-qualified domain name (FQDN) for the system.
    The FQDN can consist of letters and numbers, as well as the characters underscore ( _ ), dash ( - ), or period ( . ).
  12. Type the
    Management Port Route
    .
    The management port IP address must be in Classless Inter-Domain Routing (CIDR) format. For example:
    10.10.10.10/24
    .
  13. Select an option for what you want BIG-IQ to use for the
    Discovery Address
    .
    BIG-IQ uses this address for bi-lateral communication with its managed BIG-IP devices.
    When choosing whether to use the management port or a self IP address, consider the long-term ramifications. Changing the discovery address is a lengthy process that includes rediscovering all managed BIG-IP devices. If your deployment includes a data collection device (DCD) cluster, you would also need to reset and rebuild the entire cluster to change the discovery address for this BIG-IQ.
    • To use the management port, select
      Use Management Address
      .
    • To use the internal self IP address, select
      Self IP Address
      , and type the IP address.
      If the BIG-IQ is configured to use a self IP address for device discovery and that address cannot be found, BIG-IQ will use the management IP address instead.
      If you are configuring BIG-IQ to manage applications in a service scaling group (SSG), use the internal self IP address.
      If you plan to manage both IPv4 and IPv6 devices, you must configure an additional interface. BIG-IQ does not manage both protocols on the same interface. You can use a self IP address for this. So if your deployment includes DCDs, your discovery address will use one internal self IP address and you will need to add a second self IP to facilitate discovery of both protocol types.
      The self IP address must be in Classless Inter-Domain Routing (CIDR) format. For example:
      10.10.10.10/24
      .
  14. If you want to create a self IP address, click the
    Create
    button in the
    Self IPs
    section.
  15. If you want to associate a VLAN with the new self IP address, click
    Create
    button in the
    VLANs
    section.
  16. Click the
    Next
    button at the bottom of the screen.
  17. In the
    DNS Lookup Servers
    field, type the IP address of your DNS server.
    You can click the
    Test Connection
    button to verify that BIG-IQ can reach that IP address.
  18. In the
    DNS Search Domains
    field, type the name of your search domain.
    The DNS search domain list allows the BIG-IQ system to search for local domain lookups to resolve local host names.
  19. In the
    Time Servers
    field, type the IP addresses of your Network Time Protocol (NTP) server.
    You can click the
    Test Connection
    button to verify that BIG-IQ can reach the IP address.
  20. From the
    Time Zone
    list, select your local time zone, then click
    Next
    .
  21. After you review the details, click
    Launch
    and then click
    Restart
    to confirm.

Manual license and initial setup for BIG-IQ systems

You must have a base registration key before you can license the BIG-IQ system. If you do not have a base registration key, contact the F5 Networks sales group (
f5.com
). After you set up your BIG-IQ VE or set up your BIG-IQ 7000 Series, you can install the BIG-IQ software license.
If the BIG-IQ system is not connected to the public internet, you can follow these steps to contact the F5 license web portal then perform the initial setup.
  1. Use a browser to log in to BIG-IQ by typing
    https://
    <management_IP_address>
    , where
    <management_IP_address>
    is the address you specified for device management.
    The first time you log in to the BIG-IQ, you use
    admin
    for the
    Username
    and
    Password
    ; but then you must change the admin password.
  2. Change the default admin password.
    1. For
      Current Password
      , type
      admin
      .
    2. Type a new password in the
      New Password
      and
      Re-type New Password
      fields.
    3. Click
      Save
      . BIG-IQ changes the admin password and then displays the initial log in page.
    4. Login to the BIG-IQ user interface using your new password.
    When you change the admin password as part of an initial login, BIG-IQ also resets the root password to match it. During initial setup, you can change them both again.
  3. Select
    License
    .
  4. For
    Activation Method
    , select
    Manual
    and click the
    Get Dossier
    button.
    The BIG-IQ system refreshes and displays the dossier in the
    Device Dossier
    field.
  5. Select and copy the text displayed in
    Device Dossier
    .
  6. Click the
    Click here to access F5 Licensing Server
    link.
    The Activate F5 Product site opens.
  7. Into the
    Enter your dossier
    field, paste the dossier.
    Alternatively, if you saved the file, click the
    Choose File
    button and navigate to it.
  8. Click
    Next
    .
    • If you are setting up this device for the first time, the Accept User Legal Agreement screen opens. To accept the license agreement, select
      I have read and agree to the terms of this license
      , and click
      Next
      . The licensing server creates the license key text.
    • If you have set up this device before, the licensing server goes right to generating the license text.
  9. Copy all of the text from the text box. This is your manual license key.
  10. In the
    License Text
    field on BIG-IQ, paste the license text.
  11. Click the
    Activate
    button.
  12. Click the
    Next
    button at the bottom of the screen.
  13. Type a
    Passphrase
    that satisfies the requirements specified on screen, and then type the same phrase for
    Confirm Passphrase
    , and then click the
    Next
    button.
    BIG-IQ uses the passphrase to generate a master key. For a BIG-IQ high availability (HA) configuration, this passphrase must be the same on all BIG-IQ systems or they won't be able to communicate with each other.
    • Make sure you keep track of the passphrase, because it cannot be recovered if you lose it.
    • You must have the passphrase used to generate the master key before you can change the master key.
    • Finally, when you backup and restore a BIG-IQ, the master key is backed up with the rest of the data, and you cannot restore that data onto a BIG-IQ that has a different master key.
    If you are setting up a Microsoft Azure VE, and you type an entry in any of the fields, you will not be able to continue successfully. The only way to proceed is to leave all of the fields empty and click the
    Next
    button at the bottom of the screen. This allows the system to use the first-time access credentials you specified previously.
  14. Specify an (optional) admin and root password and click the
    Next
    button.
  15. For System Personality, select
    BIG-IQ Central Management
    and click the
    Next
    button.
    You cannot undo this choice. Once you license a device as a BIG-IQ Central Management, you can't change your mind and license it as a BIG-IQ Data Collection Device.
  16. In the
    Hostname
    box, type a fully-qualified domain name (FQDN) for the system.
    The FQDN can consist of letters and numbers, as well as the characters underscore ( _ ), dash ( - ), or period ( . ).
  17. Type the
    Management Port Route
    .
    The management port IP address must be in Classless Inter-Domain Routing (CIDR) format. For example:
    10.10.10.10/24
    .
  18. Select an option for what you want BIG-IQ to use for the
    Discovery Address
    .
    BIG-IQ uses this address for bi-lateral communication with its managed BIG-IP devices.
    When choosing whether to use the management port or a self IP address, consider the long-term ramifications. Changing the discovery address is a lengthy process that includes rediscovering all managed BIG-IP devices. If your deployment includes a data collection device (DCD) cluster, you would also need to reset and rebuild the entire cluster to change the discovery address for this BIG-IQ.
    • To use the management port, select
      Use Management Address
      .
    • To use the internal self IP address, select
      Self IP Address
      , and type the IP address.
      If the BIG-IQ is configured to use a self IP address for device discovery and that address cannot be found, BIG-IQ will use the management IP address instead.
      If you are configuring BIG-IQ to manage applications in a service scaling group (SSG), use the internal self IP address.
      If you plan to manage both IPv4 and IPv6 devices, you must configure an additional interface. BIG-IQ does not manage both protocols on the same interface. You can use a self IP address for this. So if your deployment includes DCDs, your discovery address will use one internal self IP address and you will need to add a second self IP to facilitate discovery of both protocol types.
      The self IP address must be in Classless Inter-Domain Routing (CIDR) format. For example:
      10.10.10.10/24
      .
  19. If you want to create a self IP address, click the
    Create
    button in the
    Self IPs
    section.
  20. If you want to associate a VLAN with the new self IP address, click
    Create
    button in the
    VLANs
    section.
  21. Click the
    Next
    button at the bottom of the screen.
  22. In the
    DNS Lookup Servers
    field, type the IP address of your DNS server.
    You can click the
    Test Connection
    button to verify that BIG-IQ can reach that IP address.
  23. In the
    DNS Search Domains
    field, type the name of your search domain.
    The DNS search domain list allows the BIG-IQ system to search for local domain lookups to resolve local host names.
  24. In the
    Time Servers
    field, type the IP addresses of your Network Time Protocol (NTP) server.
    You can click the
    Test Connection
    button to verify that BIG-IQ can reach the IP address.
  25. From the
    Time Zone
    list, select your local time zone, then click
    Next
    .
  26. After you review the details, click
    Launch
    and then click
    Restart
    to confirm.

Monitoring BIG-IP statistics in BIG-IQ

Visibility of statistics in BIG-IQ depends on the version of your managed BIG-IP devices. Devices running versions 13.1.X, or earlier, have limited statistics visibility support within BIG-IQ. Below outlines the compatibility and what to expect when accessing Analytics (AVR) data within BIG-IQ. For more information, see the supporting documentation found in the
BIG-IQ Centralized Management: Monitoring and Reports
guide.

Statistics visibility of managed BIG-IP devices

The format in which statistics are presented in the BIG-IQ environment, depends on the managed version of BIG-IP and the service presented. Refer to the table to access statistics visibility, based on the managed device version. Ensure that the managed device configuration meets the requirements outlined below.
Application data is visible to SC (service cluster), Legacy, and AS3 configurations.

Minimum configuration requirements:

BIG-IP Version 13.1.x or earlier
  • Ports 22 and 443 on each BIG-IP device must be open for the BIG-IQ DCD to retrieve data.
  • There must be a Data Collection Device (DCD) configured to your BIG-IQ.
BIG-IP Version 13.1.0.5 or later
  • You must have AVR provisioned for each BIG-IP device.
  • It is strongly recommended that monitored applications and virtual servers are associated with an analytics profile (HTTP and/or TCP).
  • BIG-IQ needs to provide access on Port 443 to receive BIG-IP AVR data.
  • There must be a Data Collection Device (DCD) configured to your BIG-IQ.
    To view statistics, ensure that the licenses for your managed BIG-IP devices include root access. A BIG-IP license running in Appliance Mode, will not allow for statistics visibility in the BIG-IQ environment.

Where to view statistics

Location of service statistics per managed BIG-IP version
BIG-IP v12.1
BIG-IP v13.0
BIG-IP v13.1
BIG-IP v13.1.0.5
BIG-IP v14.0
BIG-IP v14.1
BIG-IP v15.0 or later
Device Traffic
Monitoring
DASHBOARDS
Device
Local Traffic (General)
Monitoring
DASHBOARDS
Local Traffic
Local Traffic (HTTP)
Not available to this version
Monitoring
DASHBOARDS
Local Traffic
HTTP
Local Traffic (TCP)
Not available to this version
Monitoring
DASHBOARDS
Local Traffic
TCP
DNS (General)*
Monitoring
DASHBOARDS
DNS
Network Firewall (General)
+
Monitoring
REPORTS
Security
Network Firewall
Reporting
Network Firewall information is provided by ACL, IP Reputation, and IPS.
Network Firewall (ACL)
Not applicable to this version
Monitoring
DASHBOARDS
AFM
Network Security (IP Reputation)
Not applicable to this version
Monitoring
DASHBOARDS
AFM
Network Firewall (IPS)
Not applicable to this version
Monitoring
DASHBOARDS
IPS
Web Application Security (General)
Monitoring
REPORTS
Security
Web Application Security
Reporting
Monitoring
DASHBOARDS
Web Application Security
Web Application Security (Bot)
Not available to this version
Monitoring
DASHBOARDS
Bot Traffic
DDoS (Shared Security)
Not available to this version
Monitoring
DASHBOARDS
DDoS
Behavioral DoS (Shared Security)
Not applicable to this version
Visible on the analytics tab of shared security virtual server dashboard.
Monitoring
DASHBOARDS
DDoS
:
Protected Objects
:
Selected Object Name
***
Application Summary
Applications
APPLICATIONS
(limited statistics visibility)
Applications
APPLICATIONS
Secure Web Gateway
Not available to this version
Monitoring
DASHBOARDS
SWG
SSLO**
Not available to this version
Monitoring
DASHBOARDS
SSLO
Access
Monitoring
DASHBOARDS
Access
*Top Charts are only available to BIG-IP version 13.1.0.5 or later
+
Does not require AVR on host device for visibility.
**SSLO support is available to versions 5.4 to 8.2. Please note, SSLO support depends on the compatibility with the BIG-IP device.
***BIG-IP versions 14.1 only displays transaction outcomes/ L3 protocols (depending on virtual server configuration). Version 15.0 includes limited charts and metrics for Behavioral DoS. For more information see
Monitoring Behavioral DoS protection
.